AWS - Mód 5 - Modelos de Responsabilidades, AWS Shield & WAF, Inspector, Trusted Advisor, Cloud Trail, AWS Systems Manager Flashcards

1
Q

Shared Responsibility Model

A

Security and compliance are shared responsibilities between AWS and the customer. This shared model can help reduce customer operational burdens as AWS operates, manages, and controls components from the host operating system to the virtualization layer, down to the physical security of the installations where the service operates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS Responsibility: Cloud Security

A

AWS is responsible for securing the infrastructure that runs all services offered in the AWS Cloud. This infrastructure is made up of hardware, software, networks, and installations that run AWS Cloud Services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Customer Responsibility: Cloud Security

A

Your responsibility will be determined by the AWS Cloud Services you select. This determines how many configuration operations you must perform as part of your security responsibilities. Source: AWS Documentation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS WAF

A

Web application firewall that allows you to monitor
HTTP and HTTPS requests are forwarded to an Amazon CloudFront distribution, an Amazon API Gateway RESTAPI, or an application load balancer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Shield

A

AWS provides the AWS Shield Standard
and AWS Shield Advanced for protection against DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AWS Shield Standard

A

provides all AWS customers with protection against common and more frequent infrastructure attacks (layers 3 and 4), such as SYN/UDP floods, reflection attacks, and other attack types, providing high availability for applications on AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AWS Shield Advanced

A

offers better protection against larger attacks
and more sophisticated applications running on protected Amazon EC2, Elastic Load Balancing (ELB), Amazon Cloud Front, AWS Global Accelerator, and Route 53 resources. AWS Shield Advanced protection provides always-on monitoring based on network traffic flow and active application monitoring to provide notifications of suspected incidents of DDo attacks in near real-time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Amazon Inspector

A

security vulnerability assessment service that helps improve the security and compliance of AWS resources. Amazon Inspector automatically evaluates resources to detect vulnerabilities or deviations from best practices. As a result, it generates a detailed list of security findings, prioritized by severity level. Amazon Inspector includes a knowledge base of hundreds of rules, mapped to common security standards and vulnerability definitions, which are periodically updated by AWS security researchers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS Trusted Advisor

A

online tool that provides real-time guidance to help you provision resources according to AWS best practices. Trusted Advisor checks help you optimize your AWS infrastructure, increase security and performance, reduce overall costs, and monitor service limits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS Cloud Trail

A

is an AWS service that allows you to administer, maintain compliance, and perform operational and risk audits in your AWS account. Actions performed by a user, role, or AWS service are recorded as events in CloudTrail. Events include actions performed in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances. Which AWS service will provide this assessment report?

A

Amazon Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which service enables risk auditing by continuously monitoring and logging account activity, including user actions in the AWS Management Console and AWS SDKs?

A

AWS CloudTrail
https://aws.amazon.com/cloudtrail/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which AWS Support plan provides a full set of AWS Trusted Advisor checks?

A

Enterprise and Business support.
https://aws.amazon.com/premiumsupport/plans/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

A web application running on AWS has been spammed with malicious requests from a recurring set of IP addresses. Which AWS service can help secure the application and block the malicious traffic?

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which service allows an organization to view operational data from multiple AWS services through a unified user interface and automate operational tasks?

A

AWS Systems Manager
https://aws.amazon.com/systems-manager/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which of the following is the customer’s responsibility under the AWS shared responsibility model?

A

Patching Amazon EC2 instances.
https://aws.amazon.com/compliance/shared-responsibility-model/

17
Q

Under the AWS shared responsibility model, customer responsibilities include which one of the following?

A

Configuring the operating system, network and firewall.
https://aws.amazon.com/compliance/shared-responsibility-model/

18
Q

Which of the following inspects AWS environments to find opportunities that can save money for users and also improve system performance?

A

AWS Trusted Advisor

19
Q

What does AWS Shield Standard provide?

A

Prevention against Ddos attacks

20
Q
A